Compare commits
3
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
a59b2b2cf6 | ||
|
|
c43c1f4bca | ||
|
|
567944f8d8 |
@@ -44,7 +44,9 @@
|
|||||||
**/[iI][dD]_[rR][sS][aA]
|
**/[iI][dD]_[rR][sS][aA]
|
||||||
**/[iI][dD]_[dD][sS][aA]
|
**/[iI][dD]_[dD][sS][aA]
|
||||||
**/[iI][dD]_[eE][cC][dD][sS][aA]
|
**/[iI][dD]_[eE][cC][dD][sS][aA]
|
||||||
|
**/[iI][dD]_[eE][cC][dD][sS][aA]_[sS][kK]
|
||||||
**/[iI][dD]_[eE][dD]25519
|
**/[iI][dD]_[eE][dD]25519
|
||||||
|
**/[iI][dD]_[eE][dD]25519_[sS][kK]
|
||||||
|
|
||||||
# Dependencies: restored inside the image, never copied in.
|
# Dependencies: restored inside the image, never copied in.
|
||||||
**/node_modules
|
**/node_modules
|
||||||
|
|||||||
@@ -42,4 +42,6 @@ node_modules/
|
|||||||
[iI][dD]_[rR][sS][aA]
|
[iI][dD]_[rR][sS][aA]
|
||||||
[iI][dD]_[dD][sS][aA]
|
[iI][dD]_[dD][sS][aA]
|
||||||
[iI][dD]_[eE][cC][dD][sS][aA]
|
[iI][dD]_[eE][cC][dD][sS][aA]
|
||||||
|
[iI][dD]_[eE][cC][dD][sS][aA]_[sS][kK]
|
||||||
[iI][dD]_[eE][dD]25519
|
[iI][dD]_[eE][dD]25519
|
||||||
|
[iI][dD]_[eE][dD]25519_[sS][kK]
|
||||||
|
|||||||
@@ -30,6 +30,14 @@ fmt-check, and commit.
|
|||||||
The server's stop hook shuts the HTTP server down within 5 seconds and fails
|
The server's stop hook shuts the HTTP server down within 5 seconds and fails
|
||||||
when requests are still running. A new paragraph says who owns signals and the
|
when requests are still running. A new paragraph says who owns signals and the
|
||||||
exit code.
|
exit code.
|
||||||
|
- 2026-10-04: `REPO_POLICIES.md` now says how a Go tool a repo needs on the host
|
||||||
|
is pinned (issue 37): installed with `go install` pinned to a commit hash,
|
||||||
|
never tracked as a `go.mod` tool dependency or through a `tools.go` file.
|
||||||
|
golangci-lint is unaffected, since no repo installs it on the host.
|
||||||
|
- 2026-10-04: The canonical `.gitignore` and `.dockerignore` now also keep out
|
||||||
|
`id_ecdsa_sk` and `id_ed25519_sk`, the private key files `ssh-keygen` writes
|
||||||
|
for keys backed by a hardware security key (issue 81). Their `.pub` halves
|
||||||
|
stay trackable.
|
||||||
- 2026-10-04: `package.json` now has `"license": "MIT"`, matching `LICENSE`, so
|
- 2026-10-04: `package.json` now has `"license": "MIT"`, matching `LICENSE`, so
|
||||||
yarn no longer prints "No license field" when `script/bootstrap` runs it
|
yarn no longer prints "No license field" when `script/bootstrap` runs it
|
||||||
inside the Docker phases (issue 76). That was the only yarn warning there.
|
inside the Docker phases (issue 76). That was the only yarn warning there.
|
||||||
|
|||||||
@@ -495,6 +495,11 @@ style conventions are in separate documents:
|
|||||||
|
|
||||||
Keep it POSIX sh: no arrays, no `[[`, no `grep -P`.
|
Keep it POSIX sh: no arrays, no `[[`, no `grep -P`.
|
||||||
|
|
||||||
|
A Go tool a repo needs on the host is installed with `go install` pinned to
|
||||||
|
a commit hash (`go install <package>@<commit hash>`). It is never tracked as
|
||||||
|
a `go.mod` tool dependency or through a `tools.go` file, either of which
|
||||||
|
pulls the tool's own dependencies into the repo's `go.mod` and `go.sum`.
|
||||||
|
|
||||||
- When pinning images or packages by hash, add a comment above the reference
|
- When pinning images or packages by hash, add a comment above the reference
|
||||||
with the version and date (YYYY-MM-DD).
|
with the version and date (YYYY-MM-DD).
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user